Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3066 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High8.0Red Hat

High [CVE-2026-34780] Context Isolation bypass via VideoFrame object transfer

Context Isolation bypass via VideoFrame object transfer. Red Hat rates this important (CVSS 8). Weakness: CWE-501. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Build of Podman Desktop - Tech Preview.

CVE-2026-34780
Unclassified
Apr 4, 2026
High8.1Red Hat

High [CVE-2026-34774] Memory corruption and crash due to use-after-free in offscreen rendering

Memory corruption and crash due to use-after-free in offscreen rendering. Red Hat rates this important (CVSS 8.1). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Build of Podman Desktop - Tech Preview.

CVE-2026-34774
Unclassified
Apr 3, 2026
High7.5Red Hat

High [CVE-2026-34771] Memory corruption or application crash via use-after-free in permission request handling

Memory corruption or application crash via use-after-free in permission request handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-364. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Build of Podman Desktop - Tech Preview.

CVE-2026-34771
Unclassified
Apr 3, 2026
High7.7Red Hat

High [CVE-2026-34769] Arbitrary code execution and security bypass via undocumented command-line switches

Arbitrary code execution and security bypass via undocumented command-line switches. Red Hat rates this important (CVSS 7.7). Weakness: CWE-88. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Build of Podman Desktop - Tech Preview.

CVE-2026-34769
Unclassified
Apr 3, 2026
High8.1Red Hat

High [CVE-2026-0545] Unauthenticated remote code execution via unprotected job endpoints

Unauthenticated remote code execution via unprotected job endpoints. Red Hat rates this important (CVSS 8.1). Weakness: CWE-306. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-0545
Unclassified
Apr 3, 2026
High7.4Red Hat

High [CVE-2026-35535] Privilege escalation due to failure in privilege drop calls

Privilege escalation due to failure in privilege drop calls. Red Hat rates this important (CVSS 7.4). Weakness: CWE-272. Affected package(s): rhcos, sudo, rhui5/rhua-rhel9:1779798222, rhaiis/vllm-rocm-rhel9:1782353093, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:20040 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 18 more.

CVE-2026-35535
Unclassified
Apr 3, 2026
High7.1Vendor: MediumRed Hat

High [CVE-2026-23455] check for zero length in DecodeQ931()

check for zero length in DecodeQ931(). Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-125. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:26462 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-23455
Unclassified
Apr 3, 2026
High7.8Red Hat

High [CVE-2026-31402] fix heap overflow in NFSv4.0 LOCK replay cache

fix heap overflow in NFSv4.0 LOCK replay cache. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:13936 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION); Red Hat Enterprise Linux Server Optional -EXTENSION (v. 6 ELS -EXTENSION); Red Hat Enterprise Linux Server (v. 7 ELS); Red Hat Enterprise Linux for Real Time (v. 7 ELS); and 60 more.

CVE-2026-31402
Unclassified
Apr 3, 2026
High8.0Red Hat

High [CVE-2026-34742] Model Context Protocol (MCP) Go SDK: DNS rebinding vulnerability allows unauthorized access

Model Context Protocol (MCP) Go SDK: DNS rebinding vulnerability allows unauthorized access. Red Hat rates this important (CVSS 8). Weakness: CWE-1188. Affected package(s): devspaces/udi-rhel9:1779829736. Resolved in Red Hat advisory RHSA-2026:21772 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Dev Spaces 3.28; OpenShift Serverless.

CVE-2026-34742
Unclassified
Apr 2, 2026
High7.5Red Hat

High [CVE-2026-34601] XML structure injection via CDATA terminator

XML structure injection via CDATA terminator. Red Hat rates this important (CVSS 7.5). Weakness: CWE-91. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34601
Unclassified
Apr 2, 2026
High7.5Red Hat

High [CVE-2026-34827] Denial of Service via crafted multipart/form-data requests

Denial of Service via crafted multipart/form-data requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Logging Subsystem for Red Hat OpenShift; Red Hat 3scale API Management Platform 2.

CVE-2026-34827
Unclassified
Apr 2, 2026
High7.5Red Hat

High [CVE-2026-34829] Denial of Service via unbounded multipart file upload

Denial of Service via unbounded multipart file upload. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Logging Subsystem for Red Hat OpenShift; Red Hat 3scale API Management Platform 2.

CVE-2026-34829
Unclassified
Apr 2, 2026
High7.5Red Hat

High [CVE-2026-34785] Information disclosure via incorrect static file serving prefix check

Information disclosure via incorrect static file serving prefix check. Red Hat rates this important (CVSS 7.5). Weakness: CWE-552. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34785
Unclassified
Apr 2, 2026
High7.5Red Hat

High [CVE-2026-35385] Privilege escalation via scp legacy protocol when not preserving file mode

Privilege escalation via scp legacy protocol when not preserving file mode. Red Hat rates this important (CVSS 7.5). Weakness: CWE-281. Affected package(s): rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, openssh, rhcos, rhui5/rhua-rhel9:1779798222, rhaiis/model-opt-cuda-rhel9:1780681984. Resolved in Red Hat advisory RHSA-2026:26542 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 22 more.

CVE-2026-35385
Unclassified
Apr 2, 2026
High8.5Red Hat

High [CVE-2026-32871] Authenticated Server-Side Request Forgery via path traversal in OpenAPI path parameters

Authenticated Server-Side Request Forgery via path traversal in OpenAPI path parameters. Red Hat rates this important (CVSS 8.5). Weakness: CWE-918. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Satellite 6.18.

CVE-2026-32871
Unclassified
Apr 2, 2026
High7.5Red Hat

High [CVE-2026-31937] Denial of Service via DCERPC buffering inefficiency

Denial of Service via DCERPC buffering inefficiency. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-31937
Unclassified
Apr 2, 2026
High7.5Red Hat

High [CVE-2026-31935] Denial of Service via HTTP2 continuation frame flooding

Denial of Service via HTTP2 continuation frame flooding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-31935
Unclassified
Apr 2, 2026
High7.5Red Hat

High [CVE-2026-31934] Denial of Service via quadratic complexity in URL search of MIME-encoded SMTP messages

Denial of Service via quadratic complexity in URL search of MIME-encoded SMTP messages. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-31934
Unclassified
Apr 2, 2026
High7.5Red Hat

High [CVE-2026-31933] Denial of Service due to specially crafted network traffic

Denial of Service due to specially crafted network traffic. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-31933
Unclassified
Apr 2, 2026
High7.5Red Hat

High [CVE-2026-31932] Denial of Service due to inefficiency in KRB5 buffering

Denial of Service due to inefficiency in KRB5 buffering. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-31932
Unclassified
Apr 2, 2026

← All vendors